I don't think I did. Security is obviously not a black-and-white thing, and my words "on par" and "close" are entirely consistent with a shades-of-grey view.
Nonetheless, the posterior distribution shifts based on new evidence.
Are you making a claim about which one is more secure? I'm genuinely curious about how they stack up against one another. pdf.js is obviously managed code, which I'm sure helps. But it also seems like it has less person-power behind it, now and historically. Do you agree with that perception? Why or why not?